CVE-2026-31049
Received
Received - Intake
Remote Code Execution via CSV Injection in Hostbill
Publication date: 2026-04-14
Last updated on: 2026-04-16
Assigner: MITRE
Description
Description
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hostbill | hostbill | 2025-11-24 |
| hostbill | hostbill | 2025-12-01 |
| hostbill | hostbill | From 2025-11-27 (inc) |
| hostbill | hostbill | to 2025-12-01 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1236 | The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product. |